Junglewise Threat Intelligence

CVE-2025-66281: QNAP QTS and QuTS hero NULL pointer dereference

CVE-2025-66281 · Severity: info · CVSS 6.9 · Published 2026-06-10

Technologies: QNAP Systems, Inc. QuTS hero. Vendors: QNAP Systems, Inc..

Executive brief

A vulnerability has been identified in QNAP operating systems used to manage Network Attached Storage (NAS) devices. A remote attacker could exploit this flaw to cause the system to crash or become unresponsive, leading to a denial-of-service. This impact prevents legitimate users from accessing stored data or using network services until the system is recovered.

Technical details

A NULL pointer dereference (CWE-476) exists in several QNAP operating system versions, including QTS and QuTS hero. The vulnerability can be triggered by a remote attacker over the network without requiring authentication or user interaction. Successful exploitation leads to a denial-of-service (DoS) by causing the affected system component to crash. QNAP has released security updates for QTS 5.2.9, QuTS hero h5.2.9, h5.3.4, and h6.0.0 to address this issue.

Affected products

  • QNAP Systems, Inc. QTS 5.2.x versions prior to 5.2.9.3410 build 20260214
  • QNAP Systems, Inc. QuTS hero h5.2.x prior to h5.2.9.3410 build 20260214; h5.3.x prior to h5.3.4.3500 build 20260520; h6.0.x prior to h6.0.0.3397 build 20260206

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References

Related threats